HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICPHIHEALTH_BASICLowContained
Health Services Agency
bd_67348f2bdea69711 · schema v1 · pii pii-v1
Full breach record for Health Services Agency →Stanislaus County Health Services Agency reported a data security incident involving its third-party vendor, Aesto, LLC. The breach affected AWS infrastructure between December 2 and December 18, 2025. Aesto confirmed that a limited amount of protected health information (PHI) and personal identifiers (names) of patients may have been accessed. The agency notified affected healthcare providers on July 10, 2026. Aesto offered credit monitoring and identity protection services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-627513
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2026
- Raw hash
- 64116dea02916078950c9eee1a5f8f87f8b7c5609db3593d925d6ddc6da1b20d
Reporting entity
- Name
- Stanislaus Countynorm: stanislaus county
- Domain
- stancounty.com
Victim entity
- Name
- Health Services Agencynorm: health services agency
- Domain
- schsa.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.